Malware Analysis CashU.com site compromised ?

The obfuscated JavaScript was added to the end of the jQuery/Owl Carousel libraries and some other scripts on April 29th on the CASHU servers - and targeting jQuery and Owl Carousel libraries would also be a good attack-point.

Microsoft manually started flagging the scripts after I intentionally put them onto VirusTotal by the morning afterwards. It wasn't an existing detection such as through a generic signature they might have created for something else.

If all of this was genuinely a false positive, why wouldn't CASHU have had more information earlier on for everyone or an explanation as to why all of these issues occurred in the first place?
 
Last edited by a moderator: